RHSA-2026:65121HighCVSS 8.1

Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.4.2

Published
September 8, 2026
Last Modified
September 17, 2026

🔗 CVE IDs covered (18)

CVE-2026-73548 · pendingCVE-2026-73549 · pendingCVE-2026-73550 · pendingCVE-2026-73551 · pendingCVE-2026-33818CVE-2026-39825CVE-2026-50572 · pendingCVE-2026-73546 · pendingCVE-2026-73552 · pendingCVE-2026-56853CVE-2026-56858CVE-2026-56859CVE-2026-56862CVE-2026-73513 · pendingCVE-2026-73547 · pendingCVE-2026-73553 · pendingCVE-2026-56860CVE-2026-73511 · pending

📋 Description

CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-39825 — net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls CVE-2026-50572 — envoy: envoy: ext_authz use-after-free after rejecting an HTTP request CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-73511 — envoy: envoy: path matching bypass via per-segment parameters not stripped by router CVE-2026-73513 — envoy: envoy: HTTP/2 trailers without END_STREAM in oghttp2 cause heap use-after-free CVE-2026-73546 — envoy: envoy: stored XSS through dynamically generated stat names in admin interface CVE-2026-73547 — envoy: envoy: ext_authz crash on CONNECT requests without :path pseudo-header CVE-2026-73548 — envoy: envoy: connection poisoning through generic non-WebSocket HTTP upgrade requests CVE-2026-73549 — envoy: envoy: scoped IPv6 handling crash for HTTP/3 clients in original DST clusters CVE-2026-73550 — envoy: envoy: HTTP/2 memory exhaustion via discarded Host headers not counted in limits CVE-2026-73551 — envoy: envoy: path normalization bypass via dot/dot-dot segments with parameters CVE-2026-73552 — envoy: envoy: RBAC safe_regex fails to match non-UTF-8 HTTP header values CVE-2026-73553 — envoy: envoy: RBAC authorization bypass when path-parameter stripping is enabled

🎯 Affected products26

  • Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:515be58d5e748a866232759c832603a490dae81997156a3e52d8cd6382bf3c43_s390x as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:819e89709e4d96a5f30a0a780868dbeceeee70f25000c96cf0a1eb2d814d372c_arm64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:82df99a52ead267acbc12ad7715faf7bef62e19d17d3e13e5a98869d0778598c_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:eab4d432687f63afc6abd227cb2a2c0267d95e438148ae37de4b8d71f8b8ce24_ppc64le as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:14d5f781aebef126bdc14470e242a620de6de41544652f91db7de10df14b5fcb_ppc64le as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:1eec790881023bfbda086673555bc6dd7de66d461756ba3618a200ab43d9742c_arm64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:3305a36503024ec1f93b5569c59e28339b9725d8ec866017292e234b9fabb6e1_s390x as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:53c6ac39bd3d9efbb73bd461a43b613ac4d947def7d9072a02ed503717fe2c65_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:05b1806bc1770750c57d3413fade31100e80565dbe670c1a3b1bc556d886ad1a_ppc64le as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:66c6fd7c14dda3e35f2ddf1cc19d2e0280a5d6400fb2513d17fdff493544b510_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:ab0cd35b02cbfac2009ff348ec8ecf6ed849ac0858702823032c3c46a307e334_s390x as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:c7c1fa83732dd8bf2409000dd1a20877acd49fe648095d55a49fccc722da7084_arm64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:09f469af534a58085c5c0f3cbff6d07e8cb0520d41e72af17589cfc9219ba9f6_arm64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:500a26ca7fa58aab950aaa6b76c1b34bffd2d5bf37a7598a61c9afff2f9d2af9_s390x as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:84aa1fc478141ad70c36e9f0e7bd371b35ff12a23229a3b9551b4858f4b52c88_ppc64le as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:9e9dc9721b6ca5ee224e8748032edf69b6106192e72766ab950fa923e2b1da22_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:557c959e1791053324497a0f276a84451f8f6e7c00bfcb3bcb1c5dde57f3f652_ppc64le as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:9237ce3bb633b6ac6cb881bbf8aaacb5e01cfa1d280e3a1f0dfeed61f3541cba_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:d12d72d74232a9b161ff251310ac0a8501637e37ea447bbc56aa692208f0d4fe_s390x as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:ee24adfa657682a69b72250f6da24c60daeee35b0ee9b96704ab7e5bc6afc7b4_arm64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:b1fb2de6650acf051c4d6753d909fee9dd3f1cb5a0f81b818fd88259b2b3efdc_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:142eb9e84c5bb74802ff5845036b5c6d16a11ea3a2536a6f46087d190c78062e_ppc64le as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:9ec3d1dcbbffe6b151d13d523b89b5b31d3990b3bbb4981bb0f1bfddfae0c9ba_s390x as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:a4313ffe78162e825285e5d7730c3064116087a63f31c1ecf5aac2ee1b34aca9_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:b681608d9dc6ed8d2d08f59ff68ec316326139277642a533da2860a70292a59b_arm64 as a component of Red Hat OpenShift Service Mesh 3.4

✅ Remediation

See Red Hat OpenShift Service Mesh 3.4.2 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.4 Workaround: Increase the maximum number of query parameters allowed by setting the GODEBUG environment variable `urlmaxqueryparams` to a higher value (e.g., `GODEBUG=urlmaxqueryparams=20000`), or validate and enforce security controls on query parameters at the backend service rather than relying solely on the ReverseProxy's Rewrite or Director function for security filtering. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (21)